PT-2017-17006 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance
Published
2017-04-05
·
Updated
2019-10-03
·
CVE-2017-6339
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) versions 6.5 before CP 1746
Description
The issue concerns the mismanagement of key and certificate data. By default, IWSVA acts as a private Certificate Authority (CA) and generates digital certificates for secure HTTPS connections. It also allows administrators to upload their own certificates. An attacker with low privileges can download the current CA certificate and Private Key, which can be used to decrypt HTTPS traffic and compromise confidentiality. The default Private Key is encrypted with a weak passphrase, making it easier for an attacker to decrypt the key if the default certificate and key are used.
Recommendations
For Trend Micro InterScan Web Security Virtual Appliance (IWSVA) versions 6.5 before CP 1746, update to a version that includes CP 1746 or later to address the issue with key and certificate data mismanagement. As a temporary workaround, consider changing the default Private Key passphrase to a stronger one and restricting access to the CA certificate and Private Key to minimize the risk of exploitation.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Interscan Web Security Virtual Appliance